Malicious PDF — malware analysis report

Static analysis result for SHA-256 04de6337107d439f…

MALICIOUS

PDF

47.7 KB Created: 2020-09-02 20:08:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1c8f918e20fc3e17d40b88fd1c61623a SHA-1: 9cbc279b0a921581decb261fb394b9d562c17889 SHA-256: 04de6337107d439fc71d8111cf5cc111937b332d2100ce090c1e4839bad6c9b5
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains embedded links that redirect to a malicious domain, identified by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The PDF_SEO_LINK_FARM heuristic indicates a large number of external links, suggesting an attempt to manipulate search results or distribute malicious content. The ML classifier also strongly flagged this PDF as malicious. The primary IOC is the redirector URL, which is likely used to host or deliver the final payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/pify?keyword=wolfenstein+cyberpilot+trophy+guide
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://static.usrfiles.com/ugd/868b90_7fc74d932ca14dc28596df04162a9cee.pdf
    • https://static.usrfiles.com/ugd/3ce946_f786652b687f4da3b5406e3b1059d3f8.pdf
    • https://static.usrfiles.com/ugd/0c41e7_238878dfe4454fe584330e768709c9a2.pdf
    • https://cdn.shopify.com/s/files/1/0433/5370/2550/files/wifotosikuvew.pdf
    • https://cdn.shopify.com/s/files/1/0431/7757/4562/files/42422399209.pdf
    • https://cdn.shopify.com/s/files/1/0457/7122/7302/files/free_meal_planner_template_for_weight_loss.pdf
    • https://static.usrfiles.com/ugd/dba42a_034151bdccdc4f0aafc245b47a309f33.pdf
    • https://static.usrfiles.com/ugd/b8c837_5275b60d53e04940a0f0ca0851ebc307.pdf
    • https://static.usrfiles.com/ugd/b8c837_8bb0aa797b79453199425b3cda0fafb5.pdf
    • https://static.usrfiles.com/ugd/e33828_d69aa11e7c714344862b720e4279f470.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f4b.bin
7a0041b924929e28d8404f37edd4d073fea5e08bf54b2ba4789a5687e6d85dda
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F4B 5344 bytes
font_01_sfnt_off00008184.bin
78d0a896406238b85b3a1604fdf522de8ef22fd927d07b0ec9462868ed21e46a
pdf-font-stream PDF embedded font (sfnt) at offset 0x8184 10112 bytes
font_02_sfnt_off0000a43c.bin
7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71
pdf-font-stream PDF embedded font (sfnt) at offset 0xA43C 4324 bytes